Apple patches Safari arbitrary code execution vulnerabilities
Posted on 15 August 2014.
Apple released new versions of their Safari browser - 6.1.6 and 7.0.6 - in which they fixed multiple memory corruption problems in Webkit.


Out of the seven distinct CVE-IDs, five of the bugs were found in-house and the other two are credited to an anonymous researcher and the Google Chrome Security Team.

By setting up a web site with the malicious code, an attacker could cause arbitrary code execution or a denial of service (memory corruption and application crash) on the client's computer.

List of the related CVE-IDs:
  • CVE-2014-1384
  • CVE-2014-1385
  • CVE-2014-1386
  • CVE-2014-1387
  • CVE-2014-1388
  • CVE-2014-1389
  • CVE-2014-1390.



Author: Berislav Kucan, Director of Operations at Help Net Security.





Spotlight

Hackers indicted for stealing Apache helicopter training software

Posted on 1 October 2014.  |  Members of a computer hacking ring have been charged with breaking into computer networks of prominent technology companies and the US Army and stealing more than $100 million in intellectual property and other proprietary data.


Weekly newsletter

Reading our newsletter every Monday will keep you up-to-date with security news.
  



Daily digest

Receive a daily digest of the latest security news.
  

DON'T
MISS

Thu, Oct 2nd
    COPYRIGHT 1998-2014 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //